Critical Vulnerabilites Found via Wazuh
I recently deployed a SIEM to my local enviroment. The vulnerabilities found were alarming. These can be easily addressed, and I will detail some mitigations below.
Buffer Overflow Vulnerability
Ncurses are a library for creating Textual User Interfaces that work on a multitude of terminals. Our target - infocmp.c, is used to compare a binary terminfo entry with other terminfo entries as well change terminfo description to take advantage of the use= terminfo field. The analyze_string() function located in progs/infocmp.c, has a buffer overflow vulnerability. The Buffer overflow is a terminal handling library that affects systems running ncurses v6.4 and v6.5. Due to the fault in check while processing input data; a malfunction occurs when handling execssively long terminal capability strings. Ncurses library being a fundemental part in building TUIs, the infocmp directly compares terminfo database entries which makes it a terget processing malicious terminfo files. The CVSS score of 7.3 reflects a high severity of this flaw; but currently has an EPSS score of 1% which indicates this to be a unliekly source of exploitation. Currently no public facing examples have been reported of this exploit, but given the severity of the gap this can be targetted in a brute force style attack in the vulnerable path.Haxx Curl Use-After-Free
Libcurl is a library used for transferring data with URLs, supporting a multitude of protocols across platforms. Our target; libcurl's easy handle lifecycle, is used to manage HTTP/2 stream-dependency trees between paired handles as well control connection setup, transfer, and teardown through reset and cleanup routines. The internal state handling located in libcurl's HTTP/2 stream-dependency logic, has a use-after-free vulnerability. The use-after-free is a memory handling flaw that affects applications configuring CURLOPT_STREAM_DEPENDS or CURLOPT_STREAM_DEPENDS_E. Due to the fault in state management between curl_easy_reset() and curl_easy_cleanup(); a malfunction occurs when the reset routine frees the dependency object but leaves a dangling reference reachable through the handle's teardown path. Libcurl being a fundemental part in networked applications, the affected handles directly manage HTTP/2 stream state which makes it a target for attackers shaping heap contents to hijack control flow. The CVSS score of 9.8 reflects a critical severity of this flaw; but currently has an EPSS score of 0.89% which indicates this to be a unliekly source of exploitation. Currently no known exploitation has been reported of this vulnerability, but given the severity of the gap this can be targetted remotely without authentication or user interaction in the vulnerable path.HTTP/2 stream-dependency tree
Curl is a library for transferring data with URLs, working across a multitude of protocols and platforms. Our target - curl's cookie parsing logic, is used to store cookies set by remote servers as well scope those cookies against a domain using the Public Suffix List check. The cookie handling function located in curl's cookie parsing module, has a domain validation vulnerability. This flaw is a cookie scoping issue that affects systems running vulnerable curl builds with PSL support enabled. Due to the fault in check while processing trailing dot domains; a malfunction occurs when handling hostnames ending in a dot such as example.co.uk. Curl being a fundemental part in networked applications, the cookie jar directly scopes cookies to domains which makes it a terget for malicious servers setting "super cookies" that bypass the Public Suffix List. The CVSS score of 9.1 reflects a critical severity of this flaw; but currently has a low complexity and no privileges required which makes this an easy terget for cybercriminals. Currently no known exploitation has been reported of this vulnerability, but given the severity of the gap this can be targetted to inject cookies transmitted to unrelated third-party domains in the vulnerable path.
Sources & a Short Summary
// Sources:
https://ubuntu.com/security/CVE-2025-69720
https://osv.dev/vulnerability/ALPINE-CVE-2026-8924
https://curl.se/docs/CVE-2026-8924.html
https://curl.se/docs/CVE-2026-10536.html
https://www.sentinelone.com/vulnerability-database/cve-2026-10536/
https://app.opencve.io/cve/CVE-2025-69720
https://www.sentinelone.com/vulnerability-database/cve-2025-69720/
https://nvd.nist.gov/vuln/detail/CVE-2025-69720
https://en.wikipedia.org/wiki/Ncurses
https://hackaday.com/2025/06/17/a-gentle-introduction-to-ncurses-for-the-terminally-impatient/
https://linux.die.net/man/1/infocmp
Wrap Up
To directly address these well known vulnerabilites, we can impliment the following mitigation strategies: - CVE-2026-10536 (libcurl UAF): Upgrade libcurl to the patched release and avoid calling curl_easy_reset() on handles configured with HTTP/2 stream dependencies until updated. - CVE-2026-8924 (curl cookie/PSL bypass): Upgrade curl to 8.21.0 or later, ensuring builds include PSL support to properly scope cookies. - CVE-2025-69720 (ncurses buffer overflow): Upgrade ncurses to version 6.5-20251213 or later and avoid running infocmp against untrusted terminfo files.
« Back to Blog